Toverify the effectivenessof a third-party provider’ssecurity controls, anindependent external audit reportis thestrongestevidence.
Option A (Incorrect):Security configuration documentsare helpful butdo not confirm effectivenesswithout validation.
Option B (Incorrect):Policies and procedures outlineintent, but anaudit confirms actual implementation.
Option C (Correct):External audit reports (e.g., SOC 2, ISO 27001)provideindependent assurancethat security controls are effective.
Option D (Incorrect):Management interviews providequalitativeinsights but arenot objective evidenceof control effectiveness.
[Reference:ISACA CISA Review Manual –Domain 3: Information Systems Acquisition, Development, and Implementation– Coversthird-party risk assessments and audit assurance., , , , , , , ]
Submit